Glossary · Records and compliance

Hash chain

A sequence of records in which each record includes the hash of the one before it, so changing any earlier record breaks every later link.

A hash chain is an append-only sequence of records in which each new record includes the cryptographic hash of the record before it, so that any change to an earlier record is detectable.

How it works. NIST’s glossary, drawing on its blockchain overview NISTIR 8202, describes data bundled into blocks where each new block carries a hash of the previous block’s data. Changing any block changes its hash, which no longer matches the value stored in the next block. In the simplest form, the head of the chain after entry n is h(n) = SHA-256(h(n-1) || entry(n)). Anyone holding a recent head value can recompute the chain from the entries and check that it still arrives at the same value.

What it proves, and what it does not. A hash chain makes tampering evident. It does not stop the party that controls the log from rebuilding the whole chain after an edit. Protection comes from other people holding earlier head values: publishing the head, sending it to a counterparty, or having it signed and timestamped. Crosby and Wallach frame this as an untrusted logger kept honest by auditors who keep commitments to past states. They also point out the cost: proving that one old entry is present can mean replaying much of the chain, which is why large logs such as Certificate Transparency use Merkle trees instead.

Illustrative example. Two agents settle a refund. Each side appends a canonicalized, signed receipt to its own hash chain and sends the new head hash to the other. If either later edits the receipt, its chain no longer matches the head the other side stored.

A second meaning. The term also describes repeated hashing of one secret. The one-time password system in RFC 2289 hashes a seed N times for the first password, N-1 times for the next, and so on. An eavesdropper who sees one password cannot compute the next, because that would require inverting the hash function.

Emissar. Emissar’s Ledger module proposes signed, tamper-evident receipts of agent exchanges that both sides can retrieve and check. Status: Spec in progress.

Neighbouring terms. A tamper-evident log generalizes the idea. JCS canonicalization makes sure both sides hash the same bytes.

Sources

  1. NIST CSRC Glossary: Hash chain (source: NISTIR 8202, Blockchain Technology Overview) (accessed )
  2. Scott A. Crosby and Dan S. Wallach, Efficient Data Structures for Tamper-Evident Logging (USENIX Security 2009) (accessed )
  3. RFC 9162: Certificate Transparency Version 2.0 (accessed )
  4. RFC 2289: A One-Time Password System (February 1998) (accessed )
  5. Emissar: Ledger module (accessed )